Enterprise AI

Why your browser might be your best source of knowledge about enterprise AI activity

By Michael Leland, Vice President & Field CTO at Island

Enterprises have spent the last two years deploying AI tools with urgency, and that rapid pace is set to continue. Gartner predicts that spending on generative AI will grow by more than 80% this year alone.  

But while organisations are committing serious budgets to AI adoption, spending on deployment has significantly outpaced spending on governance. 

Most security teams can tell you which AI tools have been approved. Far fewer can tell you what employees are actually doing with them: what data is being shared, how it is being handled, or whether it is leaving the organisation entirely. Fewer yet have the ability to inventory or control the steady sprawl of Shadow AI tools. 

That visibility gap is a positioning problem, with security overlooking AI activity by focusing on the wrong layer. 

The browser is AI’s primary home 

For many employees, AI is just another tab on their browsers or a new button that appeared in their SaaS applications, rather than a separate system accessed through a dedicated portal. From generative AI platforms and coding assistants to agentic tools that automate tasks across business systems, the vast majority of enterprise AI activity happens inside the browser session. 

It’s no surprise, since the rest of the working day is mostly browser-based. Between SaaS platforms, cloud collaboration tools, financial systems, and HR applications, the browser long ago stopped being a window to work and became the primary workspace itself. 

However, security architecture has not kept pace with changing work practices. The controls most organisations depend on were built for a world of corporate networks, managed devices, and on-premise applications, designed to govern what sits at the edge of the enterprise, not what happens inside it.  

As the browser has become the centre of gravity for both productivity and AI adoption, the distance between where work happens and where security operates has become a structural problem that traditional perimeter controls cannot handle.  

What security can’t see 

When a user successfully authenticates into an application, most security stacks have done their job. This was the principal tenet of Zero Trust – identity-driven least privilege access. What happens next is largely beyond their reach. 

That blind spot is particularly acute around AI. An employee can open a new tab and begin sharing sensitive business data with a generative AI platform with no oversight from IT and security processes.  

It is an issue even with approved AI platforms, but even more dangerous with shadow AI. Without proper controls, employees and contractors can easily access and adopt unsanctioned AI tools, and most security architectures lack the mechanisms to detect it. 

Furthermore, the most important telemetry available to security teams sits inside the browser session itself: what is being accessed, by whom, what data is moving and where it is going. Yet most organisations cannot collect it because network-layer tools see traffic, not context. Endpoint agents see the device, not the application. The browser session, which generates the most consequential security signals, remains a blind spot. 

Agentic AI makes this more urgent still. Unlike generative tools that respond to a prompt, AI agents execute tasks, access systems, and move data autonomously on a user’s behalf. The speed and scale at which they operate mean that after-the-fact detection is not a viable governance model. By the time an anomaly surfaces elsewhere in the stack, the exposure has already occurred. 

Changing the focus from access to action 

A simple question has shaped enterprise security for decades: is this user permitted to reach this application? It is the right question for a perimeter-based model, but it’s no longer sufficient for a browser-based one. 

When work happens inside applications rather than at their edge, the more consequential question is what users are doing once access is granted. A legitimately authenticated employee can download a sensitive report to a personal device, paste customer data into an external AI tool, or take a screenshot of confidential information without triggering a single alert. The access was authorised, but the action was not governed. 

One of the most effective ways to regain visibility of this activity is to shift the enforcement layer into the presentation layer, starting with the browser. Security teams gain direct telemetry from the session itself: the actions users take, the data they interact with, and the context in which it moves. They can apply policy in real time, auditing and governing the exact moment of a file download or misdirected data without adding friction to legitimate workflows. 

AI-driven workforces need a new security model 

The way AI is changing how people work is also changing how security needs to be evaluated and enforced. Zero trust was the right response to the limitations of perimeter-based security. But most zero trust implementations still treat verification as a moment rather than a process, checking identity and device posture at the point of access, with relatively static controls applied afterwards.  

In an AI-driven environment, where a single session can involve sensitive data moving across multiple applications, autonomous agents acting on a user’s behalf, and unsanctioned tools, that model leaves significant gaps. 

Browser-native security is what makes zero trust continuous in practice. Because the browser is where AI activity, SaaS interaction, and data movement converge, it is the natural point to evaluate session context and enforce a dynamic policy throughout the working day rather than once at its start. Trust is not granted and held. It is assessed against what is actually happening, such as which applications are open, what data is in motion, whether the behaviour is consistent with the user’s role and the organisation’s policies. 

This distinction is increasingly vital for AI-driven workforces, where an agentic tool operating within a business system has a different risk profile from the same user reading a report. A session that begins with routine, human-driven work and moves into an unsanctioned AI platform mid-afternoon is a different context than the one most solutions were built to protect. Continuous browser-native evaluation is the best model that can keep pace with how AI-driven work is really happening.  

Author

Related Articles

Back to top button